Qualiteam
Qualiteam X-cart: vulnerabilidades y CVE
Qualiteam X-cart tiene 15 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE15
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2019-7220 | Media (6.1) | 0.84% | — | 6 jun 2019 | X-Cart V5 is vulnerable to XSS via the CategoryFilter2 parameter. |
| CVE-2017-15285 | Alta (8.8) | 2.1% | — | 12 oct 2017 | X-Cart 5.2.23, 5.3.1.9, 5.3.2.13, and 5.3.3 is vulnerable to Remote Code Execution. This vulnerability exists because the application fails to check remote file extensions before saving locally. This vulnerability can… |
| CVE-2015-5455 | Media (4.3) | 1.5% | — | 8 jul 2015 | Cross-site scripting (XSS) vulnerability in X-Cart 4.5.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors to install/. |
| CVE-2015-0951 | Media (6.5) | 1.3% | — | 5 abr 2015 | X-Cart before 5.1.11 allows remote authenticated users to read or delete address data of arbitrary accounts via a modified (1) update or (2) remove request. |
| CVE-2015-0950 | Media (4.3) | 1.2% | — | 5 abr 2015 | Cross-site scripting (XSS) vulnerability in admin.php in X-Cart 5.1.6 through 5.1.10 allows remote attackers to inject arbitrary web script or HTML via the substring parameter. |
| CVE-2015-1178 | Media (4.3) | 1.9% | — | 26 ene 2015 | Multiple cross-site scripting (XSS) vulnerabilities in cart.php in X-Cart 5.1.8 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) product_id or (2) category_id parameter. |
| CVE-2012-2570 | Media (4.3) | 1.7% | — | 15 ago 2012 | Cross-site scripting (XSS) vulnerability in products_map.php in X-Cart Gold 4.5 allows remote attackers to inject arbitrary web script or HTML via the symb parameter. |
| CVE-2007-4907 | Alta (7.5) | 8.2% | — | 17 sept 2007 | Multiple PHP remote file inclusion vulnerabilities in X-Cart allow remote attackers to execute arbitrary PHP code via a URL in the xcart_dir parameter to (1) config.php, (2) prepare.php, (3) smarty.php, (4)… |
| CVE-2006-4904 | Alta (7.5) | 7.0% | — | 21 sept 2006 | Dynamic variable evaluation vulnerability in cmpi.php in Qualiteam X-Cart 4.1.3 and earlier allows remote attackers to overwrite arbitrary program variables and execute arbitrary PHP code, as demonstrated by PHP remote… |
| CVE-2006-2827 | Crítica (9.8) | 1.3% | — | 5 jun 2006 | SQL injection vulnerability in search.php in X-Cart Gold and Pro 4.0.18, and X-Cart 4.1.0 beta 1, allows remote attackers to execute arbitrary SQL commands via the "Search for pattern" field, when the settings specify… |
| CVE-2005-1822 | Alta (7.5) | 2.4% | — | 1 jun 2005 | Multiple SQL injection vulnerabilities in Qualiteam X-Cart 4.0.8 allow remote attackers to execute arbitrary SQL commands via the (1) cat or (2) printable parameter to home.php, (3) productid or (4) mode parameter to… |
| CVE-2005-1823 | Media (4.3) | 3.6% | — | 1 jun 2005 | Multiple cross-site scripting (XSS) vulnerabilities in Qualiteam X-Cart 4.0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) cat or (2) printable parameter to home.php, (3) productid or (4)… |
| CVE-2004-0242 | Media (5) | 6.9% | — | 23 nov 2004 | X-Cart 3.4.3 allows remote attackers to gain sensitive information via a mode parameter with (1) phpinfo command or (2) perlinfo command. |
| CVE-2004-0240 | Media (5) | 1.5% | — | 23 nov 2004 | Directory traversal vulnerability in X-Cart 3.4.3 allows remote attackers to view arbitrary files via a .. (dot dot) in the shop_closed_file argument to auth.php. |
| CVE-2004-0241 | Alta (10) | 6.0% | — | 23 nov 2004 | X-Cart 3.4.3 allows remote attackers to execute arbitrary commands via the perl_binary argument in (1) upgrade.php or (2) general.php. |